SIGN IN SIGN UP

fix(builtin-deps): Builtin dependencies manifest validation (#17499)

### What does this PR try to resolve?

As part of https://github.com/rust-lang/cargo/issues/16960 this PR adds
validation checks to reject invalid forms of the manifest including
builtin dependencies, such as when they are present in the
`build-dependencies` section or combined with other sources. The
[RFC](https://rust-lang.github.io/rfcs/3875-build-std-explicit-dependencies.html#)
specifies what forms of builtin dependencies are valid.

This PR is part of a chain:
- https://github.com/rust-lang/cargo/pull/17497
- https://github.com/rust-lang/cargo/pull/17502
- https://github.com/rust-lang/cargo/pull/17498
- https://github.com/rust-lang/cargo/pull/17499
- https://github.com/rust-lang/cargo/pull/17500

### How to test and review this PR?

The PR consists of commits which add a test demonstrating some undesired
behaviour and then fixes that in the following commit. Cargo test passes
on every commit.

🤖 LLM disclosure: I used Codex to help me understand the codebase and
asked it to review my branch before sharing it upstream. I also used it
in limited (pre-arranged) ways to generate code, including resolving
merge conflicts and updating test assertions. All code was originally
written by hand.

r? @weihanglo
W
Weihang Lo committed
e2f915c85a9d7999621eae1b2d85d6d2e6bb8822
Committed by GitHub <noreply@github.com> on 9/23/2026, 3:27:19 PM